This page covers the web surfaces: the Hub at hub.toothprint.ai and this legal site. The
iPhone and iPad app is covered at the end.
Small files and storage areas a site keeps in your browser: cookies proper, plus localStorage,
sessionStorage and IndexedDB. We call all of them cookies here.
Sign-in. Firebase Authentication keeps your session in localStorage and IndexedDB under
the Hub's own origin. Without it you are signed out on every reload. There is no way to use an
account without this, so there is nothing to consent to and nothing to turn off.
Your preferences. Language, theme and the last case you had open, kept in the same place. You can clear them by clearing site data; the Hub will simply forget them.
Nothing else. There is no analytics cookie, no advertising cookie, no cross-site tracking pixel, no third-party marketing tag. We do not set a cookie banner because there is nothing on these sites that would require consent under the EU ePrivacy rules: everything listed above is strictly necessary or a preference you set yourself.
If that changes, this page changes first, and in the places where the law requires consent we will ask before setting anything.
The iPhone and iPad app uses no browser cookies. It keeps your authentication token in the device's secure storage and your settings in the app's own preferences. It links no analytics library and no advertising SDK, and analytics is disabled in its Firebase configuration — see Security Practices, Section 2.
Every page of this site loads a small consent control. Right now it shows nothing, and that is the correct behaviour: there is no optional category registered on these pages, so there is nothing to ask you about. A banner that appears when the only possible answer is "fine" trains people to click without reading, and then the one that matters gets clicked the same way.
The mechanism is built and tested now, before it is needed, for a specific reason. The day someone adds analytics, the banner gets written in the same week as the launch, and things written in that week ship with the boxes pre-ticked. Colombian law and the GDPR say the same thing in two languages: consent is never presumed. So the control exists already, with everything off, and the day a category appears it appears switched off too.
When there is something to decide, the control shows three choices of the same size: only what is necessary, choose one by one, or accept all. Rejecting is never a smaller link than accepting.
Your decision is stored with the date and the version of the text you were shown. If the text changes, you are asked again — a yes given about a different explanation is not a yes about this one.
Your browser can block or delete anything stored by a site. Blocking storage for the Hub will prevent sign-in, because the session has nowhere to live. We honour the Global Privacy Control signal where it applies, which today means there is nothing to opt out of.
Material changes are announced 30 days in advance, in the Services or by email.
Updated September 12, 2026 · Version 1.1
Version 1.1, amended 12 September 2026. Version 1.0 was published on 11 September and contained statements that a review against the running system showed to be wrong. They are corrected here rather than quietly edited, because a published document that changes without saying so is worth less than one that admits it changed: a page that said no third party ran AI inference on patient material, while a patient-photo feature was sending faces to a generative model; a security page that claimed point-in-time recovery and 12-month backups that were never configured; a deletion promise that gave one timeline for three destinations that do not run at the same speed; and a three-year destruction promise with no machinery behind it.